package repocfg import "testing" // The rule that matters most: a repository is closed unless it says otherwise. func TestVisibility(t *testing.T) { cases := map[string]bool{ "public": true, "Public": true, "private": false, "": false, // no config file at all, the push-to-create case "publik": false, // a typo must not publish anyone's code "true": false, "open": false, } for v, want := range cases { c := Default() c.Repo.Visibility = v if got := c.Public(); got != want { t.Errorf("visibility %q: Public() = %v, want %v", v, got, want) } } } func TestAccess(t *testing.T) { c := Default() c.Access.Push = []string{"lisa"} // Private: owner and pushers only, and no anonymous reader. for user, want := range map[string]bool{"john": true, "lisa": true, "mark": false, "": false} { if got := c.MayRead("john", user); got != want { t.Errorf("private MayRead(%q) = %v, want %v", user, got, want) } } // Public: everyone reads, including anonymously. c.Repo.Visibility = "public" for user, want := range map[string]bool{"john": true, "mark": true, "": true} { if got := c.MayRead("john", user); got != want { t.Errorf("public MayRead(%q) = %v, want %v", user, got, want) } } // Push is the owner plus the list, and the owner is never in the list. for user, want := range map[string]bool{"john": true, "lisa": true, "mark": false, "": false} { if got := c.MayPush("john", user); got != want { t.Errorf("MayPush(%q) = %v, want %v", user, got, want) } } // Rule 5: anyone with an account may propose, without being granted it. if !c.MayPropose("john", "mark") { t.Error("MayPropose denied a signed-in stranger on a public repository") } if c.MayPropose("john", "") { t.Error("MayPropose allowed an anonymous pusher") } c.Proposals.AcceptFrom = "push" if c.MayPropose("john", "mark") { t.Error("accept_from = push still accepted a stranger") } } // Force-push and deletion are free everywhere except the default branch. func TestForcePushAndDelete(t *testing.T) { c := Default() if !c.ForcePushAllowed("topic", "master") { t.Error("force-push to a topic branch was refused") } if c.ForcePushAllowed("master", "master") { t.Error("force-push to the default branch was allowed by default") } c.Access.AllowForcePush = []string{"master"} if !c.ForcePushAllowed("master", "master") { t.Error("allow_force_push did not take effect") } if c.DeleteAllowed("master", "master") { t.Error("the default branch could be deleted") } if !c.DeleteAllowed("topic", "master") { t.Error("a topic branch could not be deleted") } } // An archived repository is read-only except for the owner, who pushes the line that undoes it. func TestArchived(t *testing.T) { c := Default() c.Repo.Archived = true c.Access.Push = []string{"lisa"} if !c.MayPush("john", "john") { t.Error("the owner could not push to an archived repository, so it could never be unarchived") } if c.MayPush("john", "lisa") { t.Error("a collaborator could push to an archived repository") } if c.MayPropose("john", "mark") { t.Error("an archived repository accepted a proposal") } }